Analytics Rules
Microsoft Sentinel analytics rules detect threats by running scheduled or near-real-time logic against workspace data and creating alerts and incidents.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Supported | Reference |
| Graph | Gap | No supported Microsoft Graph configuration surface is recorded for this capability yet. |
| ARM | Supported | Reference |
| Bicep | Supported | Reference |
| Terraform | Supported | azurermazurerm_sentinel_alert_rule_scheduled Reference Fusion, ML behavior analytics, and some NRT rule kinds are not covered by azurerm; use azapi_resource against Microsoft.SecurityInsights/alertRules for those kinds. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |